Pyrocms records
6 published records for vendor pyrocms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2023-29689Proof of concept | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw.pyrocms · pyrocms | Critical9.8 | — | 53.5% | Aug 4, 2023 |
36Monitor | CVE-2022-37721No exploit | PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and japyrocms · pyrocms · CWE-79 | Critical9.0 | — | 0.8% | Nov 25, 2022 |
28Monitor | CVE-2020-25263No exploit | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary pluginpyrocms · pyrocms · CWE-352 | High7.1 | — | 0.6% | Oct 8, 2020 |
24Monitor | CVE-2022-35118No exploit | PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.pyrocms · pyrocms · CWE-79 | Medium6.1 | — | 0.5% | Aug 1, 2022 |
21Monitor | CVE-2024-58297No exploit | PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirectspyrocms · pyrocms · CWE-79 | Medium5.3 | — | 0.3% | Dec 11, 2025 |
17Monitor | CVE-2020-25262No exploit | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.pyrocms · pyrocms · CWE-352 | Medium4.3 | — | 0.5% | Oct 8, 2020 |
- CVE-2023-2968955Plan
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw.
CriticalCVSS 9.8Proof of conceptEPSS 53%pyrocms · pyrocmsAug 4, 2023
- CVE-2022-3772136Monitor
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and ja
CriticalCVSS 9.0No exploitEPSS 1%pyrocms · pyrocmsNov 25, 2022
- CVE-2020-2526328Monitor
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin
HighCVSS 7.1No exploitEPSS 1%pyrocms · pyrocmsOct 8, 2020
- CVE-2022-3511824Monitor
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
MediumCVSS 6.1No exploitEPSS 1%pyrocms · pyrocmsAug 1, 2022
- CVE-2024-5829721Monitor
PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirects
MediumCVSS 5.3No exploitEPSS 0%pyrocms · pyrocmsDec 11, 2025
- CVE-2020-2526217Monitor
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.
MediumCVSS 4.3No exploitEPSS 1%pyrocms · pyrocmsOct 8, 2020